OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • OpnSense + IDS/IPS with virtIO
« previous next »
  • Print
Pages: [1]

Author Topic: OpnSense + IDS/IPS with virtIO  (Read 5043 times)

don_lemon

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
OpnSense + IDS/IPS with virtIO
« on: May 02, 2018, 03:42:40 pm »
Hi, all
I have problem with Intrusion Prevention System

When I try to use it OpnSense is closing all connections, all nics is in freeze state. Only via cloud console I can to stop suricata and all traffic go without problems. I think problem is in virtualization platform provider which use OpenStack by RHEL, which use only VIRTIO type of NICS. I was googled information about it. And if I right old solution was only one – use e1000 emulation driver or physical NIC. For me – there are no other choice of NIC types. So question is there are any way to use IDS + IPS on virtio types of NIC? If I right problem is in the kernel or drivers level.

In network interfaces settings I have disabled by manual:
hardware checksum offload
hardware TCP segmentation offload
hardware large receive offload

OpnSense have active NAT service

Current version
Versions   OPNsense 18.1.6-amd64
FreeBSD 11.1-RELEASE-p9
OpenSSL 1.0.2o 27 Mar 2018

I will hope that this bug can be solved :)

Regards
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6489
  • Karma: 449
    • View Profile
Re: OpnSense + IDS/IPS with virtIO
« Reply #1 on: May 02, 2018, 03:49:32 pm »
virtio doesn't work yet ... small chance with 11.2, but only a guess. you still have to use e1000
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

don_lemon

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Re: OpnSense + IDS/IPS with virtIO
« Reply #2 on: May 03, 2018, 08:27:25 am »
Thanks for operative answer. At now I'm will be free of mine to search bugs in suricata :D And I will pray and wait new FreeBSD and kernel version with full supporting VIRTIO :D

Regards
Logged

noctarius

  • Newbie
  • *
  • Posts: 14
  • Karma: 3
    • View Profile
Re: OpnSense + IDS/IPS with virtIO
« Reply #3 on: May 05, 2018, 05:29:00 pm »
Oh ... now it makes all sense why it failed for me when I tested. I only run virtio (disk, network) with Proxmox for better performance. Interesting, thanks for the hint, so I won't have to retry ;-)
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • OpnSense + IDS/IPS with virtIO
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2